For the complete documentation index, see llms.txt. This page is also available as Markdown.

Multiple alerts associated with a single RDP connection

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

3 Hours

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Platform Alerts OR Third-Party Alerts

Detector Tags

Enhanced RDP Analytics

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Remote Desktop Protocol (T1021.001)

Severity

Informational

Description

Multiple alerts associated with a single RDP connection were triggered.

Attacker's Goals

Adversaries may use RDP for initial access or lateral movement within a network.

Investigative actions

  • Investigate the source and destination of the RDP communication.

  • Check if this communication is legitimate and expected.

  • Analyze the user and process that initiated the RDP connection.

Variations

Multiple elevated severity alerts associated with a single RDP connection

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Remote Desktop Protocol (T1021.001)

Severity

Medium

Description

RDP-related alerts include at least one medium or higher severity alert.

Attacker's Goals

Adversaries may use RDP for initial access or lateral movement within a network.

Investigative actions

  • Investigate the source and destination of the RDP communication.

  • Check if this communication is legitimate and expected.

  • Analyze the user and process that initiated the RDP connection.

Multiple alerts associated with a single RDP connection - high risk-processes

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Remote Desktop Protocol (T1021.001)

Severity

Low

Description

RDP-related alerts involve high-risk processes (service management, offensive tools, or script execution).

Attacker's Goals

Adversaries may use RDP for initial access or lateral movement within a network.

Investigative actions

  • Investigate the source and destination of the RDP communication.

  • Check if this communication is legitimate and expected.

  • Analyze the user and process that initiated the RDP connection.

Diverse alerts associated with a single RDP connection

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Remote Desktop Protocol (T1021.001)

Severity

Low

Description

RDP-related alerts show diverse post-connection activity across multiple attack stages.

Attacker's Goals

Adversaries may use RDP for initial access or lateral movement within a network.

Investigative actions

  • Investigate the source and destination of the RDP communication.

  • Check if this communication is legitimate and expected.

  • Analyze the user and process that initiated the RDP connection.

Pre-connection activity alongside abnormal RDP connection

Synopsis

Field
Value

ATT&CK Tactic

Lateral Movement (TA0008)

ATT&CK Technique

Remote Services: Remote Desktop Protocol (T1021.001)

Severity

Low

Description

Suspicious activity was detected before an abnormal RDP session was established.

Attacker's Goals

Adversaries may use RDP for initial access or lateral movement within a network.

Investigative actions

  • Investigate the source and destination of the RDP communication.

  • Check if this communication is legitimate and expected.

  • Analyze the user and process that initiated the RDP connection.

Was this helpful?